4 min read

Pinokio: One-Click Installer for Local AI Apps (GitHub, Scanned)

A desktop launcher that installs and runs local AI apps for images, video, voice and chat in one click.

Pinokio logo
✅
Scan: safe. Nothing malicious in this repository, but it is only the Electron shell: the engine that runs install scripts is the pinokiod npm package, which is not here and floats to its latest 8.x on every build. Scanned Sep 2, 2026; the full report is below.

Pinokio removes the hardest part of trying open-source AI: the install. It is a desktop app for Windows, macOS and Linux with a Discover page of scripts that each set up a project for you (image generators, video and voice models, upscalers, chat UIs and more), handling Python, Conda, Git, CUDA libraries and model downloads, then giving you a start button and a web view. Everything lives in a single ~/pinokio folder, with each app in its own directory and virtual environment, so removing an app means deleting a folder.

It is made by cocktailpeanut and has long been the way non-developers run tools like Stable Diffusion front ends, voice cloners and video models on their own GPU, with many TikTok and YouTube tutorials starting from it. The repository holds the Electron app (about 8,000 stars, MIT, release 8.2). The trust model is explicit: scripts can run any command, like a shell script. Featured scripts come from verified publishers, are transferred to the official Pinokio Factory GitHub organisation and reviewed before listing; anything you install from elsewhere is on you.

Who it is for

People with a decent GPU who want to try local AI apps without learning Python environments, and creators who move between many tools and want them in one launcher.

Getting started

1. Download the installer for your platform (Pinokio.exe, .dmg, .AppImage, .deb or .rpm) from the latest release

open https://github.com/pinokiocomputer/pinokio/releases/latest

2. Open Pinokio, choose Discover, and install an app with one click

open https://pinokio.co

3. Or run the app from source

git clone https://github.com/pinokiocomputer/pinokio.git && cd pinokio && npm install && npm start

Each app Pinokio installs can download several gigabytes of dependencies and models. Stick to featured scripts on the Discover page; a script from an arbitrary URL can run any command on your machine, and Pinokio shows the source repository before it runs one so you can check it.

Safety scan

We cloned pinokiocomputer/pinokio at commit 0765ab1 on Sep 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • A small repository: 41 files and about 8,000 lines of JavaScript, with no secrets, no pattern hits, no committed binaries and no bare-IP URLs. It talks only to pinokio.co, the project's GitHub Pages site and Electron's sites.
  • package.json depends on pinokiod ^8.2.0, which holds the script runner, the package managers and the Discover page logic, and there is no lockfile, so neither pinokiod nor any other dependency could be checked against advisories. The build also copies patched versions of electron-builder's yarn.js and @electron/rebuild over node_modules (npm run monkeypatch), a packaging workaround worth knowing about if you build it yourself.
  • The trust model is the real risk, and the README is upfront about it: a Pinokio script can run any command. Featured scripts are reviewed and frozen in the Pinokio Factory GitHub organisation; anything else runs with your user's permissions.
  • One postinstall script, electron-builder's native dependency rebuild. Two workflows, none using pull_request_target; none of the 4 third-party actions is pinned. Licence present; no security policy, Dependabot, CodeQL or contributing guide, and a single listed contributor.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 npm lifecycle script
Committed binariesNone.
CI workflows2 workflows. None use pull_request_target. 4 of 4 third-party actions pinned to a tag rather than a commit.
Network hosts5 distinct hosts referenced from source; most often pinokiocomputer.github.io, pinokio.co, github.com, www.electronjs.org. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

npm lifecycle scripts (1)
  • package.json postinstall: electron-builder install-app-deps

By the numbers

Stars8,197
Forks828
Contributors1
Commits677
Open issues463
Open pull requests11
Releases294
Latest releasev8.2.0
LicenceMIT
Main languageJavaScript
Project age3 years
Last pushSep 2, 2026
Tracked files41
Lines of code7,982
Checkout size1 MB

Lines by language: JavaScript 6,784, YAML 478, HTML 451, JSON 174, Markdown 87, Shell 8.

Questions

Is Pinokio free?

Yes. Pinokio is MIT-licensed and free, and so are the scripts on its Discover page. The apps it installs keep their own licences, which vary from MIT to non-commercial model licences, so check each one if you plan commercial use.

Is Pinokio safe?

Pinokio is as safe as the scripts you run with it. Featured scripts are reviewed by the maintainer, frozen in the official GitHub organisation, and checked to install only inside ~/pinokio and per-app virtual environments. Scripts from outside the Discover page get no review and can do anything a shell script can.

What hardware do I need for Pinokio?

Pinokio itself is light. The apps are the demanding part: most image and video models want an NVIDIA GPU with 8 GB or more of memory or an Apple Silicon Mac, and plenty of disk space. Each app's page in Pinokio lists what it supports.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.